Live data from Hacker News

Why I Hope Congress Never Watches “Blackhat”

wired.com

41–46 of 46 posts

Re: Why I Hope Congress Never Watches “Blackhat”

#42

Earlier quoted context omitted.

>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.

Yes, stealing something is a crime whether the item is locked or not. However, cases like that of the Weev guy ( http://en.wikipedia.org/wiki/Weev ) are very different than someone coming into an unlocked garage and stealing your stuff. His case is more like a going into a store that is open and invites you in (this was a public website he went to). You are browsing around, looking at stuff for sale.. you then see an…

> If I send a standard request to a website, with no special forged auth or anything, and that website gives me back data, you can't blame the person who made the request. It is up to the website to tell me "no, you are not allowed to access that."

Many remote exploits are going to fit this description. Sometimes it's just magic parameters or misconfigured URL routes.

Your concept of computer crime requires a bit more depth than that. Intent matters, as does what you do with data on their end and on your end.

The room analogy may be reasonable. Except weev realized the room contained private company records. He proceeded to copy everything, then went home and published it in the newspaper. He wasn't really prosecuted for the entering of the room, it was that second part that did it.

Re: Why I Hope Congress Never Watches “Blackhat”

#43
post #39

Earlier quoted context omitted.

>In particular are comic cases of when companies fail to secure things at all and then someone gets prosecuted because they "hacked" that company and "stole" that data. If I leave my garage open, and somebody takes my golf clubs, is that not theft? Yes, the potential punishments are disproportionately harsh. Yes, the company is silly for leaving data exposed. No, it's not ok to take data because it's unprotected.

If your garage says "Come on in" and, when the person takes your golf clubs, you say, "OK!" then yes, it's OK. And that's exactly what publicly accessible URLs and a status code 200 are. You had a chance to issue a 403 (ie, "You can't take my clubs") but instead you said "OK." I think it's egregious that anybody anywhere can be held criminally liable for accessing information available as a the result of a 200, with…

If you're a robot that's true, but you're probably not a robot.

The law leans on the word "reasonable" all the time, simply because there are plenty of situations where humans can make an obvious judgement call.

If a publicly accessible URL contains obviously priveleged information, as an adult you know that it is a "door that has been left open accidentally". That doesn't mean you're free to walk in and take what you want. If you're neighbourly, you may want to let them know their door is open. People should feel safe from litigation if they do that, but I don't see why you should feel like you can do whatever you want just because there's a 200.

Re: Why I Hope Congress Never Watches “Blackhat”

#44
post #39

Earlier quoted context omitted.

If your garage says "Come on in" and, when the person takes your golf clubs, you say, "OK!" then yes, it's OK. And that's exactly what publicly accessible URLs and a status code 200 are. You had a chance to issue a 403 (ie, "You can't take my clubs") but instead you said "OK." I think it's egregious that anybody anywhere can be held criminally liable for accessing information available as a the result of a 200, with…

If you're a robot that's true, but you're probably not a robot. The law leans on the word "reasonable" all the time, simply because there are plenty of situations where humans can make an obvious judgement call. If a publicly accessible URL contains obviously priveleged information, as an adult you know that it is a "door that has been left open accidentally". That doesn't mean you're free to walk in and take what yo…

> The law leans on the word "reasonable" all the time

Far too often in my estimation, and in the wrong places.

> If you're neighbourly, you may want to let them know their door is open.

Agreed. But failing to be neighbourly is not a reasonable criminal offence.

> but I don't see why you should feel like you can do whatever you want just because there's a 200.

To turn things around: Why not hold AT&T liable? Why not issue a 403?

I agree that weez was "un-neighbourly," but at the end of the day, the protocol was the only contractual arrangement in place at that moment. It's just maddening to me to imagine that this can be regarded as criminal conduct.

Re: Why I Hope Congress Never Watches “Blackhat”

#45
post #44

Earlier quoted context omitted.

If you're a robot that's true, but you're probably not a robot. The law leans on the word "reasonable" all the time, simply because there are plenty of situations where humans can make an obvious judgement call. If a publicly accessible URL contains obviously priveleged information, as an adult you know that it is a "door that has been left open accidentally". That doesn't mean you're free to walk in and take what yo…

> The law leans on the word "reasonable" all the time Far too often in my estimation, and in the wrong places. > If you're neighbourly, you may want to let them know their door is open. Agreed. But failing to be neighbourly is not a reasonable criminal offence. > but I don't see why you should feel like you can do whatever you want just because there's a 200. To turn things around: Why not hold AT&T liable? Why not i…

I'm not saying you must be neighbourly.

If the Goatse security guys had discovered the exploit, shrugged and ignored it then absolutely nothing would have happened.

They chose to write scripts, pull all the data, send it to Gawker, etc. There's no question that they knew what they were doing is wrong (because of the IRC logs) so you don't even need a judge to decide what was reasonable.

Re: Why I Hope Congress Never Watches “Blackhat”

#46
post #40

Earlier quoted context omitted.

Contact your rep in congress and tell them that. They dont read hackerness unfortunately.

Really? And you think they won't assume you're some nasty hacker trying to angle for weak laws so you can just get away with more of this demonic evil hateful hacking thing that you do? Hoodlum! The incompetency here is not striking in the fact there's apparently been no change since 1984.

> Hoodlum!

I think there's a valid concern that we would be seen this way if we contacted our reps.

This is why I think it's important that you present and carry yourself well, be prepared about what you want to talk about, and anticipate questions by having well-thought-out answers ready. These people consider themselves professionals, so despite our views of them, we will better communicate our points if we demonstrate professionalism and respect.

Post reply on HN